Expert Advice Community

Guest

Information security on managed offices

  Quote
Guest
Guest user Created:   Jul 10, 2019 Last commented:   Jul 10, 2019

Information security on managed offices

I was wondering if you can help me out with a 27001 question. I have a client that is in a managed office and therefore does not own the door to their office and employees of the managed office space access their office (to deliver post, let contractors in out of hours to do work, cleaners etc). I don't believe they are allowed to put their own lock on the door so how can this satisfy A.11 or does it need to be excluded from scope?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 10, 2019

Answer:

If I understood correctly, this managed office is the main premise of your customer, so it can not be excluded from the scope.

If your client does not have much control over the managed office to demand implementation of physical controls related on section A.11, then he should focus on protecting the assets on workstations he uses, and for this he must consider defining a clear desk and clear screen policy to ensure unattended information or equipment is removed from desk and screen when not in use or the user is absent.

Specifically for notebooks you can recommend the use of screen filters that reduce the angle of view from which other personnel can see what is in the screen (with these filters people have to be exactly in front of the screen to see something.)

If want to see how this policy looks like, I suggest you to take a look at the free demo of our Clear desk and clear screen policy at this link: https://advisera.com/27001academy/documentation/clear-desk-and-clear-screen-policy/

This article will provide you further explanation about clear desk and clear screen policy:
- Clear desk and clear screen policy – What does ISO 27001 require? https://advisera.com/27001academy/blog/2016/03/14/clear-desk-and-clear-screen-policy-what-does-iso-27001-require/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 10, 2019

Jul 10, 2019